During an investigation into suspicious internet traffic, we identified two vulnerabilities in the USGS’ IT security posture: web-site access and open USB ports. Common methods to prevent malware incidents involve a combination of employee training (Rules of Behavior) and access controls (hardware and software technologies).
We made two recommendations to help the USGS improve its IT security posture.